﻿using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Configuration;
using System.Configuration.Provider;
using System.Data.SqlClient;

namespace _114sct
{
    public partial class _Default : System.Web.UI.Page
    {
        private string connectionString;
        protected void uploadclick(object sender, EventArgs e)
        {
            if (Page.IsPostBack)
            {
                ConnectionStringSettings ConnectionStringSettings =
                      ConfigurationManager.ConnectionStrings["cj"];

                if (ConnectionStringSettings == null || ConnectionStringSettings.ConnectionString.Trim() == "")
                {
                    throw new ProviderException("Connection string cannot be blank.");
                }

                connectionString = ConnectionStringSettings.ConnectionString;
                SqlConnection conn = new SqlConnection(connectionString);
                SqlCommand cmd = new SqlCommand("insert into [dbo].[114sct_brand] ([brandUrl],[brandName],[contact],[category],[keyword],[other],[credentials])" +
                                              "values(@brandurl,@brandname,@contact,@category,@keyword,@other,@credentials)", conn);
                cmd.Parameters.Add("@brandurl", System.Data.SqlDbType.NVarChar).Value = Request.Params["brandurl"];
                cmd.Parameters.Add("@brandname", System.Data.SqlDbType.NVarChar).Value = Request.Params["brandname"];
                cmd.Parameters.Add("@contact", System.Data.SqlDbType.NVarChar).Value = Request.Params["contact"];
                cmd.Parameters.Add("@category", System.Data.SqlDbType.NVarChar).Value = Request.Params["category"];
                cmd.Parameters.Add("@keyword", System.Data.SqlDbType.NVarChar).Value = Request.Params["keyword"];
                cmd.Parameters.Add("@other", System.Data.SqlDbType.NVarChar).Value = Request.Params["other"];
                cmd.Parameters.Add("@credentials", System.Data.SqlDbType.NVarChar).Value = Request.Params["credentials"];
                try
                {
                    conn.Open();
                    cmd.ExecuteNonQuery();
                    Page.ClientScript.RegisterStartupScript(this.GetType(),"success","<script>alert('提交成功');</script>");
                }
                catch (SqlException ex)
                {
                    throw ex;
                }
                finally
                {
                    conn.Close();
                }

            }
        }
    }
}
